Sign inSign up
OpenCost

dhi.io/opencost

OpenCost 2.5.x

CIS
linux/amd64
debian 13
Tags:

2, 2-debian, 2-debian13, 2.5, 2.5-debian, 2.5-debian13, 2.5.3, 2.5.3-debian, 2.5.3-debian13

Index digest:

sha256:f44c055f28fec7ed325368eed88252969fcbd86e63ff455a1b7cc11f63fc9732

Manifest digest:

sha256:d70eeec346d4260c548d9478de6fe4fd0de2302e724386eb7c87359dbe9a4069

Size

33.29 MB

Last pushed

5 hours ago

Vulnerabilities

0
0
0
0
0

Support

Active

Overview

Docker Hardened Images include comprehensive security attestations that verify the image's build process, contents, and security posture. This image is built using SLSA Build Level 3 practices. Additionally, this image includes a source attestation that links to a corresponding source image containing all build materials. The following attestations are available and can be verified using cosign.⁠

Docker's DHI public key is available at https://registry.scout.docker.com/keyring/dhi/latest.pub⁠ and also archived at https://github.com/docker-hardened-images/keyring⁠.

How to verify attestations

1. List all available attestations

docker scout attest list dhi.io/opencost:2

2. Verify a specific attestation

For example, to verify the SLSA provenance attestation:

docker scout attest get dhi.io/opencost:2 --predicate-type https://slsa.dev/provenance/v0.2 --verify

Attestations

All attestations are signed and can be verified with cosign.⁠

PredicatePredicate typeReference
CycloneDX SBOM v1.6https://cyclonedx.org/bom/v1.6dhi.io/opencost@sha256:08fc519cd6f806ef288d1b4e1b6e4429508e1af53e9990a852f0f39ac5b04188
Changelog v0.1https://docker.com/dhi/changelog/v0.1dhi.io/opencost@sha256:f97eb738b05feafbf3c20090fd7a3eae384405ff079482974d878f9e8ab0fad3
DHI Image Sources v0.1https://docker.com/dhi/source/v0.1dhi.io/opencost@sha256:b73e059335d2f1484ad02eb93943bec6499d66032f67fcbdd94b2342d762d6da
CVEs v0.2https://in-toto.io/attestation/vulns/v0.2dhi.io/opencost@sha256:8161f330a24a89d7947914568f6f65d847bbab272f8b28eeed6c0a4c0194250d
VEX v0.2.0https://openvex.dev/ns/v0.2.0dhi.io/opencost@sha256:4dd8a860d5c42bd789fcd45ca65265cec008bfe614b6fead1159aff1786b9144
Scout provenance v0.1https://scout.docker.com/provenance/v0.1dhi.io/opencost@sha256:c5bb9d44d34808d6b1c78ae0c0131ee57e8460548c4b25dc7683ac44e124d63a
Scout SBOM v0.1https://scout.docker.com/sbom/v0.1dhi.io/opencost@sha256:8fbfe490bc9b426a0dc7e2b472e5147e6e2deee8912e533e3a3034d53f447043
Secrets scan v0.1https://scout.docker.com/secrets/v0.1dhi.io/opencost@sha256:56987cf9ad3ce7a747fbb4c606a37826c5a682648867010519d7ee5d235d1191
Tests v0.1https://scout.docker.com/tests/v0.1dhi.io/opencost@sha256:20391f2be2d3adb5d1b4f7bf8f0b0fc2f644a27bcf8e252948e8339b6247d063
Virus scan v0.1https://scout.docker.com/virus/v0.1dhi.io/opencost@sha256:14158a3abd9f7cbfba5724edee48fd7d40b05f6443f35295ba5999b9672644ff
CVEs v0.1https://scout.docker.com/vulnerabilities/v0.1dhi.io/opencost@sha256:0e7b8f9780d24718412f528bfd3cc9679aa6a9c036fec430c6fedce78af02cf5
SLSA provenance v0.2https://slsa.dev/provenance/v0.2dhi.io/opencost@sha256:83a2eb6288052601fb70f306f68d9600e853ab593d35c108643ed1fae3b45769
SLSA provenance v1https://slsa.dev/provenance/v1dhi.io/opencost@sha256:8ca63a728938714802424e74d7ac7432621425a3297f43f6b8d3a3d85d6644e2
SLSA verification summary v1https://slsa.dev/verification_summary/v1dhi.io/opencost@sha256:0334bf952c1d9bcce7b84fb897a9d671b5c9cf1da511fc3fdd98c8891784a861
SPDX SBOMhttps://spdx.dev/Documentdhi.io/opencost@sha256:e3d4616177a6d9523316e6fda766d5156253d4b21ca33c3ec27f483c1b72599d